| 2025 | CCS | NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js. | Eric Cornelissen, Musard Balliu |
| 2024 | WWW | Unveiling the Invisible: Detection and Evaluation of Prototype Pollution Gadgets with Dynamic Taint Analysis. | Mikhail Shcherbakov, Paul Moosbrugger, Musard Balliu |
| 2021 | NDSS | SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the Web. | Mikhail Shcherbakov, Musard Balliu |
| 2021 | QRS | Security-Aware Multi-User Architecture for IoT. | Marcus Birgersson, Cyrille Artho, Musard Balliu |
| 2020 | CCS | InSpectre: Breaking and Fixing Microarchitectural Vulnerabilities by Formal Analysis. | Roberto Guanciale, Musard Balliu, Mads Dam |
| 2019 | CCS | An Empirical Study of Information Flows in Real-World JavaScript. | Cristian-Alexandru Staicu, Daniel Schoepe, Musard Balliu, Michael Pradel, Andrei Sabelfeld |
| 2019 | ICSA | Flaws in Flows: Unveiling Design Flaws via Information Flow Analysis. | Katja Tuma, Riccardo Scandariato, Musard Balliu |
| 2018 | CCS | If This Then What?: Controlling Flows in IoT Apps. | Iulia Bastys, Musard Balliu, Andrei Sabelfeld |
| 2017 | ESORICS | We Are Family: Relating Information-Flow Trackers. | Musard Balliu, Daniel Schoepe, Andrei Sabelfeld |
| 2016 | ESORICS | Let's Face It: Faceted Values for Taint Tracking. | Daniel Schoepe, Musard Balliu, Frank Piessens, Andrei Sabelfeld |
| 2014 | CCS | Automating Information Flow Analysis of Low Level Code. | Musard Balliu, Mads Dam, Roberto Guanciale |
| 2011 | PLDI | Epistemic temporal logic for information flow security. | Musard Balliu, Mads Dam, Gurvan Le Guernic |
| 2009 | PLDI | A weakest precondition approach to active attacks analysis. | Musard Balliu, Isabella Mastroeni |